rdmsm4x-changelog-20260902-1321-tyrell-ios-cloudkit-snapshot
rdmsm4x-changelog-20260902-1321-tyrell-ios-cloudkit-snapshot
Implemented and committed an isolated, read-only iOS CloudKit fleet-snapshot reader so a future signed Tyrell iOS build can show sanitized remote cluster and node evidence without treating CloudKit as operational authority.
Scope
- Host:
rdmsm4x; source-only worktree/Users/richh/dev/_worktrees/tyrell-ios-cloudkit-20260902. - Commit:
9b2a22da112a407f9824a02f4661703360a28caconcodex/tyrell-ios-cloudkit-20260902. - Ticket:
TASK-20260902-05, claimed bycodex@rdmsm4x/ios-cloudkit-20260902. - No canonical checkout, Build 8 integration worktree, physical device, fleet service, signing state, or CloudKit production record was modified.
Changed files
ios/Sources/MobileCloudSnapshot.swift: strict privateTyrellClusterSnapshotreader, entitlement/account/retry/error state, whitelist validation, provenance/staleness projection, and in-memory test seam.ios/project.yml: imports existing localECSCloudKitpackage for app and test targets.ios/Sources/MobileStores.swiftandios/Sources/FleetView.swift: initialize and render the snapshot as a sanitized, explicitly non-authoritative Fleet section.ios/Tests/TyrellMobileTests.swift: contract, malformed-field, account-retention, and in-memory pull tests; plus test-only compatibility alignment for the shared chat transport interface/order.SESSION-STATE.md: isolated-worktree checkpoint and next action.
Validation
cd ios && xcodegen generate --spec project.ymlpassed.- iOS simulator XCTest passed: 22 cases, 0 failures, including 5 CloudKit snapshot tests.
swift testpassed: existing output reports 248 + 65 + 51 cases, 0 failures.git diff --checkpassed.- The authorized iPhone 17 Pro simulator
9A616E58-92CC-4635-AFA3-66D23CB454C8was shut down after tests.
Privacy and rollback
The accepted CloudKit schema excludes raw chat, prompts, provider
databases, memory, tokens, and credentials. It is a read-only private
projection; a later master-side publisher and separately provisioned
physical canary are required. Historic chat remains a future
privacy-design phase. To undo a later integration before deployment,
revert 9b2a22da112a407f9824a02f4661703360a28cac; this work
created no remote records.
Durable references
- Integration handoff:
/Users/richh/dev/_handoff/tyrell-ios-cloudkit-implementation.md - Handoff SHA-256:
2054cd7d325f10337c921c1650a8141a079509fb041253ff080041b10bb7e5cf